Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.851325
Kategorie:SuSE Local Security Checks
Titel:openSUSE: Security Advisory for Chromium (openSUSE-SU-2016:1496-1)
Zusammenfassung:The remote host is missing an update for the 'Chromium'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'Chromium'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Chromium was updated to 51.0.2704.79 to fix the following vulnerabilities:

- CVE-2016-1696: Cross-origin bypass in Extension bindings

- CVE-2016-1697: Cross-origin bypass in Blink

- CVE-2016-1698: Information leak in Extension bindings

- CVE-2016-1699: Parameter sanitization failure in DevTools

- CVE-2016-1700: Use-after-free in Extensions

- CVE-2016-1701: Use-after-free in Autofill

- CVE-2016-1702: Out-of-bounds read in Skia

- CVE-2016-1703: Various fixes from internal audits, fuzzing and other
initiatives

Also includes vulnerabilities fixed in 51.0.2704.63 (boo#981886):

- CVE-2016-1672: Cross-origin bypass in extension bindings

- CVE-2016-1673: Cross-origin bypass in Blink

- CVE-2016-1674: Cross-origin bypass in extensions

- CVE-2016-1675: Cross-origin bypass in Blink

- CVE-2016-1676: Cross-origin bypass in extension bindings

- CVE-2016-1677: Type confusion in V8

- CVE-2016-1678: Heap overflow in V8

- CVE-2016-1679: Heap use-after-free in V8 bindings

- CVE-2016-1680: Heap use-after-free in Skia

- CVE-2016-1681: Heap overflow in PDFium

- CVE-2016-1682: CSP bypass for ServiceWorker

- CVE-2016-1683: Out-of-bounds access in libxslt

- CVE-2016-1684: Integer overflow in libxslt

- CVE-2016-1685: Out-of-bounds read in PDFium

- CVE-2016-1686: Out-of-bounds read in PDFium

- CVE-2016-1687: Information leak in extensions

- CVE-2016-1688: Out-of-bounds read in V8

- CVE-2016-1689: Heap buffer overflow in media

- CVE-2016-1690: Heap use-after-free in Autofill

- CVE-2016-1691: Heap buffer-overflow in Skia

- CVE-2016-1692: Limited cross-origin bypass in ServiceWorker

- CVE-2016-1693: HTTP Download of Software Removal Tool

- CVE-2016-1694: HPKP pins removed on cache clearance

- CVE-2016-1695: Various fixes from internal audits, fuzzing and other
initiatives

Affected Software/OS:
Chromium on openSUSE 13.2

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-1672
BugTraq ID: 90876
http://www.securityfocus.com/bid/90876
Debian Security Information: DSA-3590 (Google Search)
http://www.debian.org/security/2016/dsa-3590
https://security.gentoo.org/glsa/201607-07
RedHat Security Advisories: RHSA-2016:1190
https://access.redhat.com/errata/RHSA-2016:1190
http://www.securitytracker.com/id/1035981
SuSE Security Announcement: openSUSE-SU-2016:1430 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.html
SuSE Security Announcement: openSUSE-SU-2016:1433 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.html
SuSE Security Announcement: openSUSE-SU-2016:1496 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-1673
http://www.ubuntu.com/usn/USN-2992-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-1674
Common Vulnerability Exposure (CVE) ID: CVE-2016-1675
Common Vulnerability Exposure (CVE) ID: CVE-2016-1676
Common Vulnerability Exposure (CVE) ID: CVE-2016-1677
Common Vulnerability Exposure (CVE) ID: CVE-2016-1678
Common Vulnerability Exposure (CVE) ID: CVE-2016-1679
Common Vulnerability Exposure (CVE) ID: CVE-2016-1680
Common Vulnerability Exposure (CVE) ID: CVE-2016-1681
Common Vulnerability Exposure (CVE) ID: CVE-2016-1682
Common Vulnerability Exposure (CVE) ID: CVE-2016-1683
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00002.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00003.html
http://lists.apple.com/archives/security-announce/2016/Jul/msg00005.html
BugTraq ID: 91826
http://www.securityfocus.com/bid/91826
Debian Security Information: DSA-3605 (Google Search)
http://www.debian.org/security/2016/dsa-3605
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA/
Common Vulnerability Exposure (CVE) ID: CVE-2016-1684
Common Vulnerability Exposure (CVE) ID: CVE-2016-1685
Common Vulnerability Exposure (CVE) ID: CVE-2016-1686
Common Vulnerability Exposure (CVE) ID: CVE-2016-1687
Common Vulnerability Exposure (CVE) ID: CVE-2016-1688
Common Vulnerability Exposure (CVE) ID: CVE-2016-1689
Common Vulnerability Exposure (CVE) ID: CVE-2016-1690
Common Vulnerability Exposure (CVE) ID: CVE-2016-1691
Common Vulnerability Exposure (CVE) ID: CVE-2016-1692
Common Vulnerability Exposure (CVE) ID: CVE-2016-1693
Common Vulnerability Exposure (CVE) ID: CVE-2016-1694
Common Vulnerability Exposure (CVE) ID: CVE-2016-1695
Common Vulnerability Exposure (CVE) ID: CVE-2016-1696
Debian Security Information: DSA-3594 (Google Search)
http://www.debian.org/security/2016/dsa-3594
RedHat Security Advisories: RHSA-2016:1201
https://access.redhat.com/errata/RHSA-2016:1201
http://www.securitytracker.com/id/1036026
SuSE Security Announcement: SUSE-SU-2016:1490 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00004.html
SuSE Security Announcement: openSUSE-SU-2016:1489 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00003.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-1697
Common Vulnerability Exposure (CVE) ID: CVE-2016-1698
Common Vulnerability Exposure (CVE) ID: CVE-2016-1699
Common Vulnerability Exposure (CVE) ID: CVE-2016-1700
Common Vulnerability Exposure (CVE) ID: CVE-2016-1701
Common Vulnerability Exposure (CVE) ID: CVE-2016-1702
Common Vulnerability Exposure (CVE) ID: CVE-2016-1703
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.